<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<Events>
  <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    <System>
      <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}"/>
      <EventID>4731</EventID>
      <Version>0</Version>
      <Level>0</Level>
      <Task>13826</Task>
      <Opcode>0</Opcode>
      <Keywords>0x8020000000000000</Keywords>
      <TimeCreated SystemTime="2020-06-05T13:25:20.6541388Z"/>
      <EventRecordID>36</EventRecordID>
      <Correlation ActivityID="{c0f04e29-3b3c-0000-d34f-f0c03c3bd601}"/>
      <Execution ProcessID="680" ThreadID="684"/>
      <Channel>Security</Channel>
      <Computer>DESKTOP-4AR7BIA</Computer>
      <Security/>
    </System>
    <EventData>
      <Data Name="TargetUserName">Hyper-V Administrators</Data>
      <Data Name="TargetDomainName">Builtin</Data>
      <Data Name="TargetSid">S-1-5-32-578</Data>
      <Data Name="SubjectUserSid">S-1-5-18</Data>
      <Data Name="SubjectUserName">MINWINPC$</Data>
      <Data Name="SubjectDomainName"/>
      <Data Name="SubjectLogonId">0x3e7</Data>
      <Data Name="PrivilegeList">-</Data>
      <Data Name="SamAccountName">Hyper-V Administrators</Data>
      <Data Name="SidHistory">-</Data>
    </EventData>
  </Event>
</Events>
